home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sun.admin
- Path: sparky!uunet!haven.umd.edu!darwin.sura.net!spool.mu.edu!yale.edu!ira.uka.de!math.fu-berlin.de!unidui!rrz.uni-koeln.de!Germany.EU.net!mcsun!sunic!seunet!green!hans
- From: hans@smab.se (Hans C Larsson)
- Subject: Re: Need to let Non-Root use Mount
- Message-ID: <1992Dec15.083131.15980@smab.se>
- Organization: Saab Missiles AB, RLD-Gbg, Sweden
- References: <CKD.92Dec12142530@loiosh.eff.org> <1992Dec15.025821.1233@newsserver.rrzn.uni-hannover.de>
- Date: Tue, 15 Dec 92 08:31:31 GMT
- Lines: 20
-
- riepe@ifwsn4.ifw.uni-hannover.de (Michael Riepe) writes:
-
- >In article 92Dec12142530@loiosh.eff.org, ckd@eff.org (Christopher Davis) writes:
- >|> MR> What are you talking about ? On this system (Sparc10, SunOS 4.1.3)
- >|> MR> the shell scripts below work fine with owner=root and perms=4755
- >|> MR> (and there is also a similar version for the floppy disk).
-
- >|>[Seriously, folks, setuid scripts are a BAD BAD BAD BAD idea.]
-
-
- Try making a symbolic link called "-i" (sic) to a Bourne sh(1) setuid
- shell script, execute it and "whoami" at the prompt...
-
- This is stopped by the "-b" flag to csh(1).
-
- Note that I didn't say that csh(1) was 100 % secure...
- --
- ------------------------------------------------------------
- Hans C Larsson Email: hans@smab.se
- Saab Missiles, Sweden Motto: "keep it short"
-